CVE-2025-61732

Published: February 5, 2026Last modified: February 11, 2026

Description

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

Severity score breakdown

ParameterValue
Base score8.6
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoFixed (1.24.13-r0)
25 LTSgoFixed (1.24.13-r0)
StreamgoFixed (1.25.7-r0)
Hardened Containers23 LTSgoFixed (1.24.13-r0)
25 LTSgoFixed (1.24.13-r0)
StreamgoFixed (1.25.7-r0)

References

ON THIS PAGE